Practical guidance on vendor oversight, Reg S-P compliance, and TPRM for RIA compliance teams — grounded in what examiners actually check, not trend pieces.
A vendor due diligence questionnaire for RIAs should cover cybersecurity, Reg S-P safeguards, subcontractor use, financial stability, and ongoing monitoring commitments.
No fixed interval exists. Standard practice: annual review for vendors touching client data, cybersecurity, or investment ops — continuous monitoring between reviews, and immediate ad hoc review after a breach, material change, or new subprocessor. Annual-only no longer satisfies SEC scrutiny.
Reg S-P's June 3, 2026 deadline requires RIAs to oversee service providers with access to customer data. Here's what that actually means in practice.